Slashdot Mirror


Microsoft Plans Largest-Ever Patch Tuesday

CWmike writes "Microsoft said it will deliver its largest-ever number of security updates on Tuesday to fix 13 flaws in every version of Windows, as well as Internet Explorer (IE), Office, SQL Server, important developer tools and Forefront Security client software. Among the updates will be the first for the final, or release to manufacturing, code of Windows 7, Microsoft's newest operating system. The 13 updates slated for next week, eight of them pegged 'critical,' beat the previous record of 12 updates shipped in February 2007 and again in October 2008." Update Reader Kurt Seifried writes to correct the math a bit, pointing to Microsoft's Advance Notification page for the release, which says that rather than 13 flaws, this Patch Tuesday involves "13 bulletins (eight critical and five important), addressing 34 vulnerabilities ... Most of these updates require a restart so please factor that into your deployment planning."

33 of 341 comments (clear)

  1. But will it let me buy stuff using paypal? by randy+of+the+redwood · · Score: 4, Interesting

    I am still worried about using Ebay to buy my star wars collectables from my Chrome Browser - http://it.slashdot.org/story/09/10/06/2118211/Null-Prefix-SSL-Certificate-For-PayPal-Released

    --
    The sun is the same in a relative way, but you are shorter of breath and one day closer to death
  2. EVERY version of Windows? by CSMatt · · Score: 4, Funny

    Does this mean that my Windows 3.1 box will finally get the DST update?

    1. Re:EVERY version of Windows? by Tumbleweed · · Score: 4, Funny

      No, you'll have to move to Arizona. Sorry.

      I'd rather use Windows 3.1 than live in Arizona.

    2. Re:EVERY version of Windows? by Tumbleweed · · Score: 5, Funny

      Coming from someone whose ID is Tumbleweed?

      You bet. Arizona's so bad the plants evolved to get outta there!

  3. ...Patch Tuesday by steelscalp · · Score: 4, Insightful

    Last week's "critical updates" were two copies of Windows Genuine Annoyance.

    1. Re:...Patch Tuesday by Fluffeh · · Score: 4, Interesting

      Well, they can be called critical. It's subjective you see. Critical to you as a user, or critical to Microsoft as a business?

      Yes, I think there is something in that for all of us, don't you? *puffs pipe*

      --
      Moved to http://soylentnews.org/. You are invited to join us too!
    2. Re:...Patch Tuesday by Entropius · · Score: 3, Insightful

      It's a very good security strategy to piss off all your customers with WGA and Windows Media bullshit until they all turn off automatic updates.

    3. Re:...Patch Tuesday by Elwood+P+Dowd · · Score: 4, Insightful

      MS requires customers to install the new WGA on a regular basis. That is also nagging.

      --

      There are no trails. There are no trees out here.
    4. Re:...Patch Tuesday by Anonymous Coward · · Score: 5, Interesting

      I built my system myself which means that I'm more than capable of grabbing a bootleg copy of Windows online. Instead I chose to pay for a copy of WinXP because the OS is a MAJOR part of my system and as such was worth the asking price. (And also because I'm not a thieving schmuck. If you don't want to pay use Linux.)

      Ever since I've been hounded by WGA. I just want my system patched. Microsoft wants to verify "something", god knows what, every time I try to access patches. Their checker needs updating quite often. I don't know what it does. I don't know what info it sends them. I just know it's an annoyance, maybe a personal security risk. I can't patch without it. (Officially that is. I'm aware of "alternate" patch sources but how secure is that? Seriously now, come on...)

      This is the thanks I get for dropping money on their product. I passed on Vista. I'll pass on Win7. Once this system has aged to the point of uselessness (translation: can't game any more) I'm going to Linux full time. Why? BECAUSE THEY ACT AS IF THEY OWN MY MACHINE, NOT ME. THAT pisses me off.

      So f--- them. I'm done.

    5. Re:...Patch Tuesday by Mr.+Roadkill · · Score: 3, Informative

      That's now at www.wsusoffline.net

  4. Long Weekend by camperdave · · Score: 3, Insightful

    Isn't Tuesday the first day back from a long weekend? Is that really the best time to do this? We'll be up to our eyeballs in password resets already. (How do people forget a password in three days?)

    --
    When our name is on the back of your car, we're behind you all the way!
    1. Re:Long Weekend by Fluffeh · · Score: 5, Insightful

      How do people forget a password in three days?

      Because people are stupid. A person is smart, but people are stupid.

      One of the most strangely insightful comments in Men in Black from memory.

      --
      Moved to http://soylentnews.org/. You are invited to join us too!
    2. Re:Long Weekend by PrimaryConsult · · Score: 3, Insightful

      How do people forget a password in three days?

      Duh, the janitor who comes in on holidays keeps throwing out the post-its taped to the monitors!

  5. Re:The more crap you add... by CannonballHead · · Score: 3, Insightful

    I'd like to see a comparison between the number of patches to Linux vs. Windows. :)

    Which do I think is a better OS in terms of security and stability? Linux. But I tend to get tired of the "Microsoft releases so many patches, their OS is obviously bad" argument when the it seems the whole development model of open source software (e.g., Linux distros) is that anyone can develop both features and patches, thus improving the software.

  6. Bad luck by gmuslera · · Score: 4, Funny

    13 patches released at 13:00 of Tuesday 13. Windows sysadmins that day will have to pass below ladders, see a black cats cross in front of them and then break a mirror. But that will be nothing. The worst part will be when they turn on the computer, and see that windows is still running.

  7. Re:Autodestruct? by BenBoy · · Score: 3, Funny

    Will it make every PC that uses windows ME self-destruct?

    Nope, that doesn't require a patch; it was built into the original release ...

  8. Re:The more crap you add... by Penguinisto · · Score: 5, Insightful

    I'd like to see a comparison between the number of patches to Linux vs. Windows. :)

    For just the kernel, or for a whole average distro? Which distro's kernel and which variant (e.g. SMP vs. uniprocessor) and which arch? (x86 vs. say, PPC or ARM)? Do we count all the optional modules, and what about the stuff that is out there which could be compiled-in, but usually isn't (e.g. Win4Lin extensions)? Are patches counted as individual diffs checked in to a CVS/SVN/BK repo source tree, or counted only if distributed .rpm/.apt packages by a vendor?

    Otherwise, yeah, I can see your POV. :)

    --
    Quo usque tandem abutere, Nimbus, patientia nostra?
  9. Re:Autodestruct? by Fluffeh · · Score: 3, Funny

    Will it make every PC that uses windows ME self-destruct?

    Not likely, PC's running Windows ME probably don't have the power to do more than to self fizzle at most. I would personally be impressed if they let out the smallest little puff of smoke. I think the reality would be that they just refuse to power up due to shame.

    --
    Moved to http://soylentnews.org/. You are invited to join us too!
  10. Re:The more crap you add... by CannonballHead · · Score: 4, Insightful

    Fair questions, but easily answered: for whatever is being compared to in a Windows OS. Windows, as I recall, has a kernel, has components that are necessary, has components that are unnecessary, etc. It seems Linux fans easily lapse into thinking that Windows is one complete mess all bound into one, whereas Linux has messy parts but the core is great... but who installs "Linux" and doesn't install a "Linux distro." To be fair to Windows. I'd have to say you'd have to compare an entire Linux distro default installation to an entire Windows default installation... all software included in the iso, not the latest-updated-version-of-Amarok or whatever comes with it by default. Getting the latest Amarok version is just like getting the latest patch for Windows Media Player...

    As for CVS/SVN/BK diff's and whatnot, that's hard to come up with... I have no clue how much code differences there are in a given Windows patch. For all I know, it's one single typo, but since it's a binary, the entire thing is built and sent over in the patch, right? So who knows? I would think, from an end-user perspective, it only counts as a patch if it's distributed in an easily installed format; e.g., as an update or as an rpm or included in the distro, etc.

    Thanks for seeing my POV. :) hehe. I'm in an unfortunate position for my life on slashdot; I actually enjoy Windows OS's. And Linux distros. Awful, I know.

    I don't like AIX though...

  11. Re:It fixes EVERY bug? by CannonballHead · · Score: 4, Funny

    Yes, those users, too. ;)

  12. Re:Autodestruct? by von_rick · · Score: 5, Funny

    Nope, that doesn't require a patch; it was built into the original release ...

    Yup. The hard drive with ME installation will jump out from the chasis, climb the refrigerator and rub itself all over the magnets.

    --

    Face your daemons!

  13. Wring. 13 advisories with 34 issues. RTFM by seifried · · Score: 4, Informative

    http://blogs.technet.com/msrc/archive/2009/10/08/october-2009-bulletin-release.aspx

    For October we are releasing 13 bulletins (eight critical and five important), addressing 34 vulnerabilities, affecting Windows, Internet Explorer, Office, Silverlight, Forefront, Developer Tools, and SQL Server. Most of these updates require a restart so please factor that into your deployment planning.

  14. Kudos by Linker3000 · · Score: 4, Interesting

    Look, I know it's fashionable to make negative remarks about MS round here, but it's only fair to say 'well done' to them for bettering their previous high count. Hopefully they haven't run out of bugs to fix and they'll work hard to find and fix even more next time. Who knows, this time next year they could be fixing hundreds of bugs every month - and if we're lucky, some of them could be quite serious or critical - wouldn't that be just awesome!

    Go MS!

    --
    AT&ROFLMAO
  15. 13 Patches != 13 Flaws by Ralish · · Score: 5, Informative

    I was about to bitch about the submitter/moderator not RTFA, but it turns out, the article doesn't mention it either, so I'll clarify instead: thirteen updates are being released which together address thirty-four security vulnerabilities of varying severity across varying products (ten of which are targetted at Windows). So, that's NOT thirteen flaws (plenty more actually), just thirteen updates, some of which (all?) address multiple flaws in the particular system they are targetted at. Of course, this is just the advance notification, so full details about how many vulnerabilities each update addresses and the general information on them won't be released until the patches are next Tuesday. I think it's also worth nothing (although the summary of course neglects to mention it) that the good aspect of these updates are both major zero-day exploits (targetting IIS & SMB 2.0) are patched with these updates.

    And while I'm posting, why does Slashdot insist on linking to shitty tech magazine articles (poorly) summarising the raw and accurate data straight from Microsoft? Seriously, I'm not sure if it's some sort of aversion to linking to MS, but they're the ones doing the patching, so it follows that they have the best, newest, most accurate data on them, and they'll likely be the first to provide updates on their content. These articles are just summarising what Microsoft has published on their various web-sites, and being a summary, they provide a lot more information and raw data:

    Microsoft Security Bulletin Advance Notification for October 2009
    October 2009 Bulletin Release Advance Notification

  16. Re:in the last patch supertuesday by plague3106 · · Score: 3, Insightful

    Well stop pirating office and you won't have those kinds of problems.

  17. Re:The more crap you add... by jrumney · · Score: 4, Insightful

    The point the GP is trying to make is that they just aren't directly comparable. Limiting yourself to the Linux kernel is unfair to Windows, as Windows is much more than just a kernel. But comparing with a full distribution is unfair to Linux, as there is much more in a distribution than even Windows + Office + SQL Server + everything else that Microsoft Update covers.

  18. Does it fix Windows 7's problems? by MBCook · · Score: 5, Funny

    Does it fix the problems with Windows 7? After reading this review of a pre-release download, I'm a bit hesitant to use it.

    --
    Comment forecast: Bits of genius surrounded by a sea of mediocrity.
  19. Re:Typical Bullshit by smash · · Score: 5, Insightful
    I've yet to see a good Linux/Unix distribution that offers centralized patch management in an easily administered manner to compare with WSUS.

    Kernel issues still require a reboot.

    I run both Linux and FreeBSD in the server room, and have for about 15 years - but in terms of managing, reporting on, and distributing updates to hundreds of desktops, there's nothing off the shelf for *nix that comes close.

    --
    I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
  20. Nice! by rrohbeck · · Score: 4, Funny

    So where are the instructions for the patch party?

  21. Please patch ALL versions of Windows! by OrangeTide · · Score: 3, Funny

    Or at least patches to Win2K would be nice, maybe some working timezone data.

    I also would highly recommend Microsoft release patches for Windows 3.11 to fix flaws in Win32s, and perhaps add IPv6 to Wolverine (winsock 1.1 for Windows for Workgroups)

    --
    “Common sense is not so common.” — Voltaire
  22. So? by Anonymous Coward · · Score: 3, Interesting

    So what?

    My Ubunutu Jaunty desktop downloaded 130mb of updates last night. And this isnt the first time either.

    I didnt see the /. community getting their nickers in a knot about it

    1. Re:So? by Teun · · Score: 3, Insightful
      You said it: Updates.

      And you didn't have to wait for the magical Patch Day for Ubuntu to share them with you.

      --
      "The likes of Facebook and WhatsApp are free to those whose privacy is of zero value."
  23. Re:Typical Bullshit by TooMuchToDo · · Score: 4, Informative
    http://www.redhat.com/spacewalk/

    We use it to manage several thousand linux servers that store and process the data that's about to come from one of the LHC detectors. Handles provisioning, RPM updates, etc. And yeah, it'll work with Linux desktops.